PatchSiren

Baserow CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Baserow CVE published 2026-08-04

CVE-2026-18817

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:14.117Z and has not been modified since then. The NVD entry is currently Received. A potential vulnerability exists in Baserow up to 2.3.2 in the Inactive Non-Staff User Handler component, related to improper authorization with a low CVSS score of 2.1. The project maintainer considers it mo [truncated]

LOW Baserow CVE published 2026-08-04

CVE-2026-18816

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T22:17:13.930Z and has not been modified since then. The vulnerability identified in Baserow up to 2.3.2 affects the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint, leading to improper authentication. The attack may be launched rem [truncated]